How can small providers implement the security standard?
The proposed security standard does not require extraordinary measures to implement. It involves taking actions that a prudent person would agree were necessary to ensure the privacy and security of the information to be protected. The standard does not dictate specific technologies. The requirements of the standard may be implemented in a number of ways, depending upon the security needs and technologies in place at each business and upon agreements among businesses that work together. The Notice of Proposed Rule Making includes an example to illustrate the manner in which a small provider might implement the standard. We expect that those required to implement the standard would first assess their security risks and vulnerabilities and the mechanisms currently in place to mitigate those risks and vulnerabilities. Following this assessment, they would determine what additional measures, if any, need to be taken to meet the security requirements.